CIOPages
All RFP packages

RFP Package · Cybersecurity & Identity

Vulnerability Management Platforms RFP questions and template

127 questions, 10 demo scenarios and a five-vendor scorecard for choosing Vulnerability Management Platforms software, in one Excel workbook.

What this package is for

Use it to run a Vulnerability Management Platforms software selection, from the first long list to the final scorecard.

What the category covers. Software that finds an organization's assets, assesses them for vulnerabilities, ranks findings by exploitability and business context, and drives remediation to a verified close. Bought by security and IT operations leaders replacing a scanner, adding risk-based prioritization or unifying several scanners into one remediation workflow.

A selection usually runs in three rounds. The package has questions for each:

  • RFI, to the long list. 27 questions screen out products that lack something you need.
  • RFP, to the shortlist. 65 questions ask how each product does the work.
  • Deep dive, to the finalists. 35 questions ask for proof on your own data.

10 demo scenarios tell each vendor what to load and what to show, so every product does the same work in front of you. 100 due-diligence questions cover security, integration, implementation and exit. The scorecard weights the answers and ranks up to five vendors.

Each question comes with why it matters, what a good answer looks like and the red flags, so the people scoring the replies know what to look for.

3 questions from the package

From the RFI round. The first shows part of the guide each question carries; the workbook adds follow-ups, how to verify the answer, a priority and a weight.

1. Provide a table of the asset discovery methods your product supports, listing the asset types each method can find.

Why it matters. If the product lacks a discovery method the buyer depends on, the assets that only that method finds stay outside the inventory and never receive a risk score.

Good answer
  • Table covers active network discovery, agents, cloud and virtualization connectors, directory imports and [CMDB] imports
  • Each method is mapped to specific asset types such as servers, workstations, network devices, cloud instances and printers
  • States which methods need an on-premises sensor or collector
Red flags
  • A list of method names with no asset types mapped to them
  • Claims that one method finds "all assets"
  • Methods that depend on a third-party product are not identified as such

2. Provide a table of the operating systems and versions your product supports, showing for each whether agent-based assessment and authenticated network scanning are available.

Why it matters. Hosts running an operating system that neither the agent nor the authenticated scan supports get only banner-level unauthenticated checks. Missing patches on those hosts go undetected.

3. Provide a table of the cloud workload types your product assesses for vulnerabilities, such as virtual machines, machine images, container images, container registries, Kubernetes clusters and serverless functions, showing for each [cloud provider] whether assessment is agentless, agent-based or both.

Why it matters. A product that covers virtual machines but not container images or serverless functions leaves whole classes of cloud workloads unassessed. The buyer may not find these gaps until after rollout.

Capability areas

Asset Discovery & Inventory (10)

Finding managed, unmanaged and shadow assets, building a single asset identity across sources, and reconciling the inventory against our CMDB. Excludes how assets are then assessed for vulnerabilities, which is covered under scanning and cloud coverage.

Scanning & Detection Methods (13)

Authenticated and unauthenticated network scanning, agent-based and agentless assessment, credential handling, scan scheduling, scan safety on fragile systems, detection accuracy, and new-check release speed. Excludes cloud-native, container and OT-specific assessment, and web application scanning (application security testing is a separate category; its findings are ingested under AGG).

Cloud, Container & Ephemeral Workloads (11)

Assessment of cloud accounts, virtual machine images, container images and registries, Kubernetes clusters, serverless functions and short-lived workloads that exist between scan windows. Excludes cloud misconfiguration and identity risk except where it feeds vulnerability findings, which are covered under exposure context.

External Attack Surface (8)

Discovery and assessment of internet-facing assets, domains, certificates and exposed services as an outside attacker would see them, including attribution of unknown assets to an owner. Excludes internal network scanning.

OT, IoT & Non-Standard Devices (9)

Identification and assessment of operational technology, IoT, medical and network devices, including passive methods that avoid disrupting controllers. Excludes standard servers, workstations and cloud workloads.

Risk-Based Prioritization (14)

How findings are ranked beyond base severity using exploit-prediction scores, known-exploited catalogs, in-the-wild and ransomware association, exploit maturity, and threat intelligence freshness. The transparency and tunability of the scoring model are in scope. Excludes business context inputs, which are covered under asset criticality.

Asset Criticality & Business Context (9)

How asset criticality, data sensitivity, business service mapping, compensating controls and ownership are captured, kept current and applied to risk scores. Excludes the external threat signals used in prioritization.

Exposure Context & Attack Paths (11)

Attack-path analysis, choke-point identification, unification of vulnerability, misconfiguration and identity findings, and validation that an exposure is reachable or exploitable in our environment. Excludes the base prioritization score and remediation workflow.

Remediation Workflow & Ticketing (13)

Grouping findings by fix, owner assignment, bidirectional ticketing with ITSM and work-tracking tools, patch and configuration management hooks, and remediation guidance. Excludes verification of closure, exceptions and SLA tracking.

Closed-Loop Verification, Exceptions & SLAs (10)

Confirmation by re-assessment that a fix landed, handling of findings that reappear, risk acceptance and exception workflow with expiry, governance of false-positive suppressions (who may suppress, review and expiry), and SLA tracking with escalation. Excludes ticket creation and routing, and detection accuracy itself, which is under SCN.

Findings Aggregation & Normalization (10)

Ingestion of findings from third-party scanners, application security tools and cloud security tools, with de-duplication, normalization to a common vulnerability and asset model, and conflict handling between sources. Excludes generic API and connector availability, which is covered by the integration module.

Reporting & Program Metrics (9)

Mean-time-to-remediate and risk burndown trends, role-based and owner-level views, executive reporting, and reports that support our compliance mandates. Excludes the vendor's own certifications.

Demo scenarios

Each scenario lists the data to load before the demo, then the steps to show, and the questions it scores.

  1. Rank the findings to fix first
  2. Trace one critical vulnerability to confirmed closure
  3. Exploited vulnerability disclosed this morning
  4. Container deployed and removed between scans
  5. Unknown internet-facing asset found and routed
  6. Two scanners on the same hosts, one ticket per fix
  7. Attack path from exposed workload to key database
  8. Risk acceptance expires and an SLA is breached
  9. Passive assessment of an OT segment
  10. Executive risk burndown by business unit

Due diligence

The workbook carries the screening questions from these modules. Each module is also sold on its own.

Questions about this package

How many Vulnerability Management Platforms RFP questions are there?

127 solution questions in 12 capability areas: 27 for the RFI, 65 for the RFP and 35 deep-dive questions for the finalists. The workbook adds 100 due-diligence questions on security, integration, implementation and exit.

What comes with each question?

Why it matters, good-answer signals, red flags, follow-up questions, how to verify the answer (a demo step, a test or a document), and a suggested priority and weight for scoring.

Can I edit the questions?

Yes. The workbook is an ordinary Excel file. Change, add or remove questions, and change the weights; the scorecard recalculates.

Which license do I need?

The Enterprise License covers any number of evaluations inside one organization. The Consultancy License covers use with any number of clients. Neither allows reselling or republishing the questions.

Before you shortlist

The buyer guide compares the products in this category and what decides between them.

Buyer Guide
Vulnerability Management Platforms

For the business side of the same change: